US11700279B2ActiveUtilityA1

Integrated security and threat prevention and detection platform

Assignee: CORVID CYBERDEFENSE LLCPriority: Jun 29, 2018Filed: Jul 1, 2019Granted: Jul 11, 2023
Est. expiryJun 29, 2038(~11.9 yrs left)· nominal 20-yr term from priority
H04L 63/1408G06F 21/577H04L 63/20H04L 63/1441H04L 63/02
61
PatentIndex Score
2
Cited by
13
References
18
Claims

Abstract

An integrated computer network security and threat prevention and detection platform includes a central processor and a display operable to aggregate and present data from a plurality of network security applications in an integrated dashboard format to a system administrator. The network security applications may be hardware, software, or hybrid applications running on local machines, local networks, remote machines, or remote networks, in communication with the central processor. In one embodiment implementation of the integrated computer network security and threat prevention and detection platform is performed on premises, in an alternative embodiment the integrated computer network security and threat prevention and detection platform is provided in an Internet or cloud-based environment, in other embodiments the computer system security platform is a hybrid configuration having both on-premises and cloud base components.

Claims

exact text as granted — not AI-modified
What is claimed, is: 
     
       1. An integrated computer network security and threat prevention and detection platform, comprising:
 a plurality of Application Program Interfaces (APIs), each corresponding to a respective one of a plurality of network security applications that collectively monitor a network comprising a plurality of computing systems, a first network security application of the plurality of network security applications configured to monitor a first network communication layer and a second network security application of the plurality of network security applications configured to monitor a second network communication layer; and 
 a central processor configured to collect network security data from the plurality of network security applications via the plurality of APIs, the network security data including data from the first network security application and the second network security application, 
 wherein the central processor is further configured to aggregate and weight the network security data, resulting in weighted aggregated data, 
 wherein the central processor is further configured to display, via a display in communication with the central processor, the weighted aggregated data within an intregrated dashboard presentation of system activity and threats within the network; 
 wherein the integrated dashboard presentation includes a threat overview display presenting a timeline view of a type and severity of a plurality of threats found in the network, and a ranking of the severity, criticality, or both severity/criticality of the plurality of threats found in the network, and 
 wherein the integrated dashboard presentation includes a single indication of an overall risk level in the network, including at the first network communication layer and at the second network communication layer, the overall risk level determined based on the weighted aggregation data. 
 
     
     
       2. The integrated computer network security and threat prevention and detection platform of  claim 1 , wherein the plurality of network security applications comprises: hardware implemented applications, software implemented applications, or combinations thereof. 
     
     
       3. The integrated computer network security and threat prevention and detection platform of  claim 1 , wherein the plurality of network security applications comprises: firewalls, network traffic monitors, access controls, email monitors, vulnerability scanners, endpoint security monitors, malware detectors, virus detectors, bandwidth usage monitors, or combinations thereof. 
     
     
       4. The integrated computer network security and threat prevention and detection platform of  claim 1 , wherein the central processor is with one or more data collection and analytic tool applications to search, collect, and parse network traffic data to collect the network security data. 
     
     
       5. The integrated computer network security and threat prevention and detection platform of  claim 1 , wherein the central processor is further configured to isolate at least one threat of the plurality of threats found in the network. 
     
     
       6. The integrated computer network security and threat prevention and detection platform of  claim 5 , wherein isolation of the at least one threat of the plurality of threats found in the network comprises restricting access to the network by a component of the network on which the at least one threat is detected. 
     
     
       7. The integrated computer network security and threat prevention and detection platform of  claim 5 , wherein isolation of the at least one threat of the plurality of threats found in the network comprises shutting down a component of the network on which the at least one threat is detected. 
     
     
       8. The integrated computer network security and threat prevention and detection platform of  claim 1 , wherein the weighted aggregated data comprises: network usage data, network threats data, application usage data, threat mitigation data, malware activity data, virus activity data, or combinations thereof. 
     
     
       9. The integrated computer network security and threat prevention and detection platform of  claim 1 , wherein the integrated dashboard presentation of system activity and threats within the network includes an aggregate view of network traffic and a threat level for the network that includes data that is unavailable from any one individual network security application of the plurality of network security applications. 
     
     
       10. A method for computer network security and threat prevention and detection, comprising:
 configuring a central processor to interface with a plurality of Application Program Interfaces (APIs), each of the plurality of APIs corresponding to a respective one of a plurality of network security applications that collectively monitor a network comprising a plurality of computing systems, at least one first network security application of the plurality of network security applications configured to monitor a first network communication layer and at least one second network security application of the plurality of network security applications configured to monitor a second network communication layer; 
 collecting, by the central processor, network security data from the plurality of network security applications via the plurality of APIs, the network security data including data from the first network security application and the second network security application; 
 aggregating and weighting, by the central processor, the network security data, resulting in weighted aggregated data; and 
 displaying, by a display in communication with the central processor, the weighted aggregated data within an integrated dashboard presentation of system activity and threats within the network, 
 wherein the integrated dashboard presentation includes a threat overview display presenting a timeline view of a type and severity of a plurality of threats found in the network and a ranking of the severity, criticality, or both severity/criticality of the plurality of threats found, and 
 wherein the integrated dashboard presentation includes a single indication of an overall risk level in the network, including at the first network communication layer and at the second network communication layer, the overall risk level determined based on the weighted aggregation data. 
 
     
     
       11. The method of  claim 10 , wherein the plurality of network security applications comprises: firewalls, network traffic monitors, access controls, email monitors, vulnerability scanners, endpoint security monitors, malware detectors, virus detectors, bandwidth usage monitors, or combinations thereof. 
     
     
       12. The method of  claim 10 , wherein the collecting, by the central processor, of the network security data comprises communicating, by the central processor, with one or more data collection and analytic tool applications to search, collect, and/or parse network traffic data to collect the network security data. 
     
     
       13. The method of  claim 10 , wherein the weighted aggregated data comprises:
 network usage data, network threats data, application usage data, threat mitigation data, malware activity data, virus activity data, or combinations thereof. 
 
     
     
       14. The method of  claim 10 , wherein the plurality of network security applications comprises: hardware implemented applications, software implemented applications, or combinations thereof. 
     
     
       15. The method of  claim 10 , further comprising:
 isolating, by the central processor, at least one threat of the plurality of threats found in the network. 
 
     
     
       16. The method of  claim 15 , wherein isolating of the at least one of the plurality of threats found in the network comprises restricting access to the network by a component of the network on which the at least one threat is detected. 
     
     
       17. The method of  claim 15 , wherein isolating of the at least one of the plurality of threats found in the network comprises shutting down a component of the network on which the at least one threat is detected. 
     
     
       18. The method of  claim 10 , wherein displaying of the integrated dashboard presentation of system activity and threats within the network includes displaying an aggregate view of network traffic and a threat level for the network that includes data that is unavailable from any one individual network security application of the plurality of network security applications.

Join the waitlist — get patent alerts

Track US11700279B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.